OpenJPEG allows OOB heap memory write in opj_jp2_read_header
Published Aug 5, 2025
6.6
MEDIUMCVSS 4.0
EPSS 0.63%
Description
OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.
Affected products
-
- Version >= 2.5.1, <= 2.5.3StatusaffectedConstraints-
- Version
No data.
Red Hat Enterprise Linux 10
openjpeg2-0:2.5.2-4.el10_0.1
Fixed · RHSA-2025:13944
Red Hat Enterprise Linux 6
openjpeg
Out of support scope
Red Hat Enterprise Linux 7
openjpeg
Not affected
Red Hat Enterprise Linux 7
openjpeg2
Not affected
Red Hat Enterprise Linux 8
openjpeg2
Not affected
Red Hat Enterprise Linux 9
openjpeg2
Not affected
Red Hat Enterprise Linux AI (RHEL AI)
libpdfium
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | openjpeg2-0:2.5.2-4.el10_0.1 | Fixed | RHSA-2025:13944 |
| Red Hat Enterprise Linux 6 | openjpeg | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | openjpeg | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openjpeg2 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | openjpeg2 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | openjpeg2 | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) | libpdfium | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability is Important rather than Moderate because it allows a malformed or truncated data stream to trigger a heap-based out-of-bounds (OOB) write, which directly corrupts memory. Unlike read-based issues or null dereference crashes that typically lead to denial of service, an OOB write has the potential to alter program control flow, leading to arbitrary code execution under certain conditions. The affected pointer p_image is dereferenced without verifying the success of the header parsing routine, and if it's left uninitialized due to a parsing failure, writing to it results in undefined behavior.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (8)
- https://access.redhat.com/security/cve/CVE-2025-54874 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2386543 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-23631 Advisory
- https://github.com/uclouvain/openjpeg/commit/f809b80c67717c152a5ad30bf06774f00da4fd2d x_refsource_CONFIRMPatch
- https://github.com/uclouvain/openjpeg/pull/1573 x_refsource_MISCThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-54874
- https://securitylab.github.com/advisories/GHSL-2025-057_OpenCV x_refsource_MISCExploitThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2025-54874
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-54874 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2386543 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-23631 | Advisory | |
| https://github.com/uclouvain/openjpeg/commit/f809b80c67717c152a5ad30bf06774f00da4fd2d | x_refsource_CONFIRMPatch | |
| https://github.com/uclouvain/openjpeg/pull/1573 | x_refsource_MISCThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-54874 | ||
| https://securitylab.github.com/advisories/GHSL-2025-057_OpenCV | x_refsource_MISCExploitThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2025-54874 |
Change history (0)
No recorded changes yet.